CVE-2018-10076: XSS
Published Jul 2, 2018
·Updated
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
Affected Software
1 affected component
ZohoCorp Manageengine Eventlog Analyzer=11.12
Event History
Jul 2, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-10076.
2
What is the severity of CVE-2018-10076?
The severity of CVE-2018-10076 is medium with a CVSS score of 6.1.
3
How does CVE-2018-10076 impact Zoho ManageEngine EventLog Analyzer?
CVE-2018-10076 allows a remote attacker to inject arbitrary web script or HTML via the search functionality of Zoho ManageEngine EventLog Analyzer.
4
What software versions are affected by CVE-2018-10076?
CVE-2018-10076 affects Zoho ManageEngine EventLog Analyzer version 11.12.
5
Is there a fix for CVE-2018-10076?
At the moment, there is no known fix for CVE-2018-10076. It is recommended to follow the vendor's security advisory for updates.